Ok, I have a Kerberos issue, before I get intot he details let me explain this did work at one time. Within the past 3 weeks it has failed.
We have an odd arangement. All employess work in the AM domain of parent.net. There is another forest/domain linked via trust to am.parent.net called ChildCompany.net. This is the IT sandbox for our department. All of our servers exist in ChildCompany.net which is in a different forest.
Forest: parent.net
Domain: am.parent.net
Forest: ChildCompany.net
Domain: ChildCompany.net
SPNs are configured for the services correctly.
Users from am.parent.net are unable to authenticate via Kerberos to my SharePoint server in the ChildCompany.net domain. Users from the ChildCompany domain are authenticated using Kerberos *even when* surfing the Sharepoint site from an am.parent.net machine. So I logged in as
rkaucher@ChildCompany.net to my PC rkauch-win7.am.parent.net and was able to surf SharePoint and received a Kerberos ticket.
Any ideas? We have rebooted the DCs in childcompany.net.